WordPress Gravity Forms Plugin <= 1.9.3.5 - SQL Injection

gravity-forms

Software
Gravity Forms
Versions
<= 1.9.3.5
Disclosure date
2015-03-17
CVE
CVE-N/A
References
Credits
Classification
SQL Injection
OWASP Top 10
A1: Injection

Are your websites subject to this vulnerability?

Details

This plugin is prone to an SQL injection vulnerability, because the sort_column GET parameter is not sufficiently sanitised before being used within an SQL query.

Solution

Update the plugin.

Found a vulnerability that puts your sites at risk?

Found a vulnerability? Help us secure the web and join our community of ethical hackers.

Are you the developer of this software? Hire our researchers for a thorough security audit.